Hutool
Hutool: vulnerabilidades y CVE
Hutool tiene 15 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses0
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-56769 | Media (6.5) | 0.34% | — | 25 sept 2025 | An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbitrary method invocation and potentially remote code execution (RCE) via the… |
| CVE-2023-51080 | Alta (7.5) | 0.62% | — | 27 dic 2023 | The NumberUtil.toBigDecimal method in hutool-core v5.8.23 was discovered to contain a stack overflow. |
| CVE-2023-51075 | Alta (7.5) | 0.65% | — | 27 dic 2023 | hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function. This vulnerability allows attackers to cause a Denial of Service (DoS) via manipulation of the first two… |
| CVE-2023-42278 | Alta (7.5) | 0.84% | — | 8 sept 2023 | hutool v5.8.21 was discovered to contain a buffer overflow via the component JSONUtil.parse(). |
| CVE-2023-42277 | Crítica (9.8) | 0.91% | — | 8 sept 2023 | hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonObject.putByPath. |
| CVE-2023-42276 | Crítica (9.8) | 0.91% | — | 8 sept 2023 | hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonArray. |
| CVE-2023-33695 | Alta (7.1) | 0.24% | — | 13 jun 2023 | Hutool v5.8.17 and below was discovered to contain an information disclosure vulnerability via the File.createTempFile() function at /core/io/FileUtil.java. |
| CVE-2023-24163 | Crítica (9.8) | 1.4% | — | 31 ene 2023 | SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine. |
| CVE-2023-24162 | Crítica (9.8) | 1.3% | — | 31 ene 2023 | Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter. |
| CVE-2022-4565 | Alta (7.5) | 0.92% | — | 16 dic 2022 | A vulnerability classified as problematic was found in Dromara HuTool up to 5.8.10. This vulnerability affects unknown code of the file cn.hutool.core.util.ZipUtil.java. The manipulation leads to resource consumption.… |
| CVE-2022-45690 | Alta (7.5) | 0.97% | — | 13 dic 2022 | A stack overflow in the org.json.JSONTokener.nextValue::JSONTokener.java component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data. |
| CVE-2022-45689 | Alta (7.5) | 0.77% | — | 13 dic 2022 | hutool-json v5.8.10 was discovered to contain an out of memory error. |
| CVE-2022-45688 | Alta (7.5) | 1.2% | — | 13 dic 2022 | A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data. |
| CVE-2022-22885 | Crítica (9.8) | 1.3% | — | 16 feb 2022 | Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation. |
| CVE-2018-17297 | Alta (7.5) | 2.7% | — | 21 sept 2018 | The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive. |